PT-2023-8787 · Veritas · Veritas Netbackup It Analytics
CVE-2023-28818
·
Publicado
2023-03-24
·
Atualizado
2023-03-31
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Veritas NetBackup IT Analytics versions prior to 11.2.0
Description
The issue is related to errors in cryptographic signature verification, which could allow a remote attacker to compromise data integrity. A malicious actor could exploit the application upgrade process, which includes unsigned files, to install rogue Collector executable files, such as
aptare.jar or upgrademanager.zip, on the Portal server. These files might then be downloaded and installed on collectors.Recommendations
For Veritas NetBackup IT Analytics versions prior to 11.2.0, update to version 11.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Portal server to minimize the risk of exploitation. Avoid using the unsigned files in the application upgrade process until the issue is resolved.
Correção
Improper Verification of Cryptographic Signature
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Veritas Netbackup It Analytics